Arachni
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
DAST
Probe a running application from the outside, the way an attacker would.
34 tools profiled
How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
Arachni Project (Tasos Laskos)
Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.
PortSwigger
Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.
Caido Labs
Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.
OpenText
Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
HCLSoftware
Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.
Syhunt
Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.
Andres Riancho and contributors
Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.